Well-known documents
The machine-readable documents this estate publishes. Each is served by the app that owns the facts in it, so there is no copy here to fall out of date — this page lists what the release ships.
Reading this from a program?
The same list is served as JSON at /.well-known/estate, grouped by the app that serves each document — 27 documents across 21 apps. It is the one address a client needs to find the rest.
Accounts
OpenID Provider metadata: the authorization, token, userinfo and end-session endpoints, supported scopes, and the JWKS location.
OAuth 2.0 Authorization Server metadata. The same issuer described in OAuth’s own vocabulary, for clients that look here rather than at the OpenID document.
The public keys that verify tokens this issuer signed. Rotating keys appear here before they are used, so a verifier that refetches keeps working across a rotation.
- products
/.well-known/productsThe public product directory: apps an organisation can discover and request. Display fields only — never platform apps, grant-only products, client fields or metrics.
- capabilities
/.well-known/capabilitiesThe accounts capabilities manifest: every served RPC action with its input and output schema, the sign-in and sign-up pages, the events it publishes, and the app, feature and permission-code catalogue shapes. No user, session, credential, token or client table is catalogued. The same document answers on system.accounts.wellknown.capabilities.v1.
Organizations
- org-basics
/.well-known/org-basicsPublic facts about the organisation that owns a custom domain. Rate limited, and it answers for public organisations only.
- ?domain=required
- The custom domain to look up. Without it the endpoint answers 400; for a domain no public organisation owns, 404.
- capabilities
/.well-known/capabilitiesThe orgs capabilities manifest: every served RPC action with its input and output schema, the public join-link page, the events it publishes, and the organisation, branch, node, group, team and role shapes with owner, creator, metadata and external-reference fields excluded. Membership rows are not catalogued. The same document answers on system.orgs.wellknown.capabilities.v1.
Storage
- capabilities
/.well-known/capabilitiesThe storage capabilities manifest: every served RPC action with its input and output schema, the public share-link route, and the file and folder shapes it exposes with object keys and uploader ids excluded. The same document answers on system.storage.wellknown.capabilities.v1.
People
- capabilities
/.well-known/capabilitiesThe people capabilities manifest: every served RPC action with its input and output schema, the events it publishes, and the person, tag and list shapes. Names, birthdays, contact points, addresses, notes, attachments and guardian invites are never catalogued. The same document answers on system.people.wellknown.capabilities.v1.
Forms
- capabilities
/.well-known/capabilitiesThe forms capabilities manifest: every served RPC action with its input and output schema, the public routes, and the row shapes it exposes with sensitive columns excluded. The same document answers on system.forms.wellknown.capabilities.v1.
Calendar
- capabilities
/.well-known/capabilitiesThe calendar capabilities manifest: every served RPC action with its input and output schema, the public calendar and feed routes, and the calendar, event and working-week shapes it exposes with share tokens and owner ids excluded. The same document answers on system.calendar.wellknown.capabilities.v1.
Notifier
- capabilities
/.well-known/capabilitiesThe notifier capabilities manifest: every served RPC action with its input and output schema, the public routes and inbound webhooks, the events it publishes, and the campaign, message and workflow shapes it exposes with tenant, recipient and provider columns excluded. The same document answers on system.notifier.wellknown.capabilities.v1.
Web
- estate
/.well-known/estateThe machine-readable index of the well-known documents this estate advertises, grouped by the app that serves it. Start here to find the rest. A product the registry hides, such as a superadmin-only app, still serves its documents at its own address but is not listed.
Where to report a vulnerability in any cmykcloud app, and the contact that answers.
Audit
- capabilities
/.well-known/capabilitiesThe audit capabilities manifest: every served RPC action with its input and output schema and the audit-event shape it exposes with actor, network and chain columns excluded. The same document answers on system.audit.wellknown.capabilities.v1.
ADMS
- capabilities
/.well-known/capabilitiesThe adms capabilities manifest: every served RPC action with its input and output schema, the device protocols it accepts, the events it publishes, and the device and punch shapes it exposes with credentials, addresses and raw device lines excluded. The same document answers on system.adms.wellknown.capabilities.v1.
Attendance
- capabilities
/.well-known/capabilitiesThe attendance capabilities manifest: its own RPC action with its input and output schema (the reserved marks contract has no caller and is not advertised), the day-judged event, and the policy, group, leave-type and day-result shapes with policy bodies, raw evidence, reasons and acting user ids excluded. The same document answers on system.attendance.wellknown.capabilities.v1.
School
- capabilities
/.well-known/capabilitiesThe school capabilities manifest: every served RPC action with its input and output schema, the events it publishes, and the academic-year, class, group, subject, classroom, section, subject-offering, period and exam shapes. Student, staff, guardian, marks and fee records are never catalogued. The same document answers on system.school.wellknown.capabilities.v1.
Teacher
- capabilities
/.well-known/capabilitiesThe teacher capabilities manifest: its own RPC action with its input and output schema. The portal owns no table and publishes no event — what a teacher sees is school’s answer, asked afresh on every request. The same document answers on system.teacher.wellknown.capabilities.v1.
Student
- capabilities
/.well-known/capabilitiesThe student capabilities manifest: its own RPC action with its input and output schema. The portal owns no table and publishes no event — what a student sees is school’s answer, asked afresh on every request. The same document answers on system.student.wellknown.capabilities.v1.
Guardian
- capabilities
/.well-known/capabilitiesThe guardian capabilities manifest: its own RPC action with its input and output schema, and the public invite route a school hands a guardian. The portal owns no table and publishes no event. The same document answers on system.guardian.wellknown.capabilities.v1.
Billing
- capabilities
/.well-known/capabilitiesThe billing capabilities manifest: its own RPC action with its input and output schema (the reserved wallet contracts have no caller and are not advertised), the product and meter model shapes, and its events, billing.invoice.finalized among them. No price, contract, wallet, hold, invoice, payment or ledger table is catalogued as a model. The same document answers on system.billing.wellknown.capabilities.v1.
Rules
- capabilities
/.well-known/capabilitiesThe rules capabilities manifest: every served RPC action with its input and output schema, and the decision and decision-version shapes it exposes with the owning organisation, the authoring user and the decision content excluded. The same document answers on system.rules.wellknown.capabilities.v1.
- capabilities
/.well-known/capabilitiesThe mail capabilities manifest: every served RPC action with its input and output schema, the public routes, and the row shapes it exposes with sensitive columns excluded. The same document answers on system.mail.wellknown.capabilities.v1.
Support
- capabilities
/.well-known/capabilitiesThe support capabilities manifest: every served RPC action with its input and output schema, the public routes, and the row shapes it exposes with sensitive columns excluded. The same document answers on system.support.wellknown.capabilities.v1.
My Portal
- capabilities
/.well-known/capabilitiesThe my capabilities manifest: its own RPC action with its input and output schema. The portal owns no table yet and publishes no event — what you see is accounts, people and school answers, asked afresh on every request. The same document answers on system.my.wellknown.capabilities.v1.
Website builder
- capabilities
/.well-known/capabilitiesThe website-builder capabilities manifest: its own RPC action with its input and output schema. The builder owns no table and publishes no event — what it renders is managed per site, asked afresh on every request. The same document answers on system.website-builder.wellknown.capabilities.v1.